Executive brief
The Simple Cloudflare Turnstile plugin for WordPress, which is used to protect websites from bots and spam, contains a security flaw that allows unauthorized users to bypass authentication checks. An attacker could exploit this to perform actions that are normally restricted to site administrators or other high-privileged users. This could lead to unauthorized changes on the website or potential account takeover.
Technical details
A broken authentication vulnerability exists in the Simple Cloudflare Turnstile plugin for WordPress (versions <= 1.38.0) due to an authentication bypass using an alternate path or channel (CWE-288). The flaw allows an unauthenticated remote attacker to bypass intended security restrictions and potentially execute actions with elevated privileges. The root cause involves improper validation of authentication states, which can be exploited over the network without user interaction. A patch is available in version 1.38.1.
Affected products
- RelyWP Simple Cloudflare Turnstile <= 1.38.0
Timeline
- 2026-04-08: other: Reported by David Marín
- 2026-05-08: advisory: Initial advisory published by Patchstack
- 2026-06-15: disclosed: NVD publication date